Disclaimer: This blog was inspired by ludicity, hence using the same platform and style. Go check him out if you haven't already, and read some of his classics if you need a good laugh.
On June 18th, CrowdStrike did an oopsie-daisy and created the world's largest IT outage to date, one that most skids and ransomware operators alike could only have wet dreams about. Somehow, this incident has caused even more mental damage for me and many other professionals, than it has physical damage to the estimated 8.5 million unfortunate machines that got bluescreened.
I have real experience writing real-world implants for both Linux and Windows. I am no windows magician or kernel dev that can pull 0days and bypasses out the oiseaux, but I can read and implement most evasive methods that come out, and have a better understanding of the actual threat landscape from an evasion/detection standpoint than these "thought leaders" on LinkedIn that wouldn't know a ZwTerminateProcess if it slapped them across the face.
So if you are going to look me dead in the eyes and tell me that you genuinely don't think we shouldn't have kernel-level antimalware drivers in this current landscape I am going to call up your local mental hospital and schedule you an appointment on my dime.
But We Just Saw What Ha-
Did I studder?
The CrowdStrike was an isolated incident that is the first of its kind after OVER 20 YEARS of vendors writing defensive software drivers for the kernel. Just because it happened once and you didn't include this in your threat model doesn't mean you need to rip out every single .sys you have installed to every endpoint you have and spend your weekend crying wolf and how "something doesn't quite feel right" when some guy made a mistake and probably pushed to the wrong branch.
Yes, the situation is unfortunate. Yes, this is the result of multiple failures mostly on CrowdStrike's shoulders. There probably should've been a better QA process. There probably should've been more testing. I am not here to defend CrowdStrike. They make a half-decent product all things considered, but this was a major screw-up. We can also blame M$FT for allowing a failing kernel driver to stay in the boot process. That is a massive oversight.
But if you tell me that you are implementing a kernel-less software policy because of this incident I am going to personally deploy an implant against your sad little windows host that will get its userland hooks stomped to ntdll and back again.
But Do We Really Need Kerne-
Please shut up.
In a world where my pillow was always cold at night, I never hit a red light, and my USB always went in the right way the first time, then MAYBE we could live in a world without kernel-level antivirus. As you may have noticed, that is not the world we live in. Forget 11, even Windows 10 is a 3rd grader's hodgepodge art project of an Operating System that still has lines of code that have existed since the 90's. The amount of complexity in userland ALONE is enough to make a career out of, and that's because a lot of it is documented. If you even want THINK about journeying into the depths of the kernel with your trusty friend windbg, I wish you the best and say my goodbyes. Between APC, HVCI, PPL, ASLR, WDAC, ELAM, CFG, ACL, KDP, TPM, MBEC, COM, DACL, EMET, CG, DCOM, TPM, and KPP (all of which are real acronyms with actual security consequences by the way) I want you to once again tell me that you DONT want some form of eyes in the kernel to watch for attacks utilizing/exploiting some of these things, and ensure their correct functions.
And keep in mind, I am STRICTLY referring to the endpoint here. Just the OS, the underlying hardware, and their security measures. It is a dumpster fire of backwards compatibility and fixes that came about 10 years too late.
We have been preaching antivirus as the BARE MINIMUM of securing your environment for years. And all of the sudden just because of one incident you forgot about all of that and want to nuke any AV you come across I will pivot into your DC and rip your CISSP certification out of your cold, ransomed hands.
B-B-But Red Teams Always Bypass It So Its Usele-
If you think this is a valid argument you have a deeply flawed understanding of security and your job as a defender.
In your 20 years as a "security practitioner" have you ever heard the term "Defense In-Depth" or did your 8 SANS classes at 10k a piece not ever teach you how to defend things in the real world. You are supposed to have MULTIPLE LAYERS of defense. You cannot just install CrowdStrike or SentinelOne and be shocked when you get a .txt file on your app server talking something about "your files being encrypted" and "sending 10000 dollars to a BTC address." These pieces of software work pretty decent all things considered, but they cannot be the only tool in your repertoire of defensive capabilities. These things exist to make an attackers job HARDER, not to stop them outright. Stopping an attacker with enough resources and knowledge is fully impossible, and any ounce of critical thinking left in you should be able to recognize that.
And removing kernel-level antivirus just adds more unnecessary holes in your already non-existent security "stack" that is just off-the-shelf email security and EDR.
So please. Think twice before you remove your EDR out of an "abundance of caution" and brag about it to the entire world online.
If you have any thoughts on this article or want to debate me, shoot me an email at genericredteamer8[at]gmail[dot]com